Privacy Policy
Reference translation. This English text is provided for the convenience of our users. The Korean version is the governing text. Where the two differ, the Korean version applies. See “Governing Language” at the end of this document.
Seonham Labs (the “Company”) treats users’ personal information as important and complies with the laws of the Republic of Korea on the protection of personal information, including the Personal Information Protection Act (「개인정보 보호법」), the Act on Promotion of Information and Communications Network Utilization and Information Protection (the “Network Act”, 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」) and the Protection of Communications Secrets Act (「통신비밀보호법」).
Through this Privacy Policy the Company tells you for what purposes and by what methods the personal information you provide is used, and what measures are taken to protect it.
This Privacy Policy was drawn up in accordance with Article 30 of the Personal Information Protection Act and applies to the “Forest of Stones” service operated by the Company, including the web and the mobile app.
This Privacy Policy may change following amendments to applicable law or guidelines, or a change in the Company’s internal policy. Any change will be announced through the in-app notices (or by individual notification).
1. Items of Personal Information Collected and Methods of Collection
1.1. Items collected
The Company collects only the minimum personal information necessary to provide the Service.
Required items
- Email address: login ID and delivery of important notifications
- Password: account security (stored encrypted using bcrypt; not collected from users who registered through social login)
- Nickname: display name for anonymous activity (2 to 10 characters; Korean, English letters or digits)
- Date of birth: to verify that the user is 19 or older (format YYYY-MM-DD)
Items collected on social login
- Social account identifier (sub ID): linking the social login and managing the account (Google sub, Apple sub)
- Social login provider: to distinguish the linked service, such as Google or Apple
- Email address (where provided): automatic linking to an existing account and delivery of notifications
Information generated and collected automatically in the course of using the Service
- Service usage records: writing worries (stones), writing replies (pebbles), sending and receiving notes, blocking and reporting activity and the like
- Note data: for a note conversation attached to a pebble, the participant identifiers (the author of the stone and the author of the pebble), whether the conversation has ended together with who ended it and when, and for each note its content (1 to 200 characters), sender identifier, time of creation and read status
- Activity data: contribution score, trust level (an internal measure) and the like
- Blocking relationship data: identifiers of the content (stones, pebbles) and users a user has blocked (for filtering the browse feed)
- Access logs: access IP address (stored after hashing), time of access, time of last login
- Device information: operating system, browser or app version, user agent
- Cookie and session information: maintaining automatic login, JWT tokens (access token, refresh token), security authentication
- Security event logs: successful and failed logins, password changes, account locks, detection of suspicious activity and the like
- Device token: Apple APNs token (iOS) and Google FCM token (Android) for sending push notifications (collected where notification permission is granted)
The Company does not collect advertising identifiers (IDFA on iOS, GAID on Android). See section 8.5 for details.
1.2. Methods of collection
- Entered directly by the user on registration
- Collected with consent to third-party provision when linking a social login (Google, Apple)
- Generated and collected automatically in the course of using the Service
2. Purposes of Collecting and Using Personal Information
In accordance with Articles 15 and 22 of the Personal Information Protection Act and Article 22 of the Network Act, the Company uses the personal information it collects only for the following purposes, and will seek the user’s prior consent if a purpose changes.
2.1. Managing members
- Verifying identity and identifying individuals in connection with the provision of a membership service
- Verifying age (use of the Service is restricted to those 19 and older)
- Preventing improper use and unauthorised use
- Restricting use by members who breach the Terms of Service
- Confirming an intention to withdraw membership and processing the withdrawal
- Retaining records of improper use of the Service and mediating disputes
2.2. Providing the Service
- Providing the core functions, including writing worries (stones), writing replies (pebbles) and note conversations (sending, receiving, replying and ending)
- Operating the trust level system (an internal measure) and managing contribution scores
- Recommending content and personalizing the Service
- Retaining and managing records of use of the Service
2.3. Customer support and handling complaints
- Responding to and handling customer enquiries
- Delivering notices and sending important notifications
- Sending service notifications by push notification (a new pebble, a note or reply received, notices and the like)
- Providing guidance on use of the Service and notifying changes
- Mediating disputes and handling complaints
2.4. Improving and developing the Service
- Developing new services and improving existing ones
- Statistical analysis (using anonymized data)
- Improving the user experience through analysis of usage patterns
- Providing the Service according to demographic characteristics
2.5. Operating a safe community
- Monitoring and blocking unlawful or inappropriate content
- Imposing and lifting sanctions
- Mediating disputes and handling complaints
- Preventing improper use of the Service and responding to security incidents
- Performing obligations under applicable law and cooperating with investigations
3. Period of Retention and Use of Personal Information
The Company retains and uses a user’s personal information from the date of registration until use of the Service ends.
3.1. On withdrawal of membership
- Immediate destruction: personally identifying information such as the email address, password, nickname, date of birth and profile image is destroyed immediately on withdrawal.
- Retention of an email hash: in order to prevent re-registration and abuse of the Service, the email address of a withdrawn member is converted into a one-way hash from which it cannot be recovered (HMAC-SHA256) and retained for 30 days from the date of withdrawal. The original email address can neither be identified nor recovered from that hash, and it is destroyed automatically when the retention period expires.
- Retention of the hash for permanently suspended members: where a member has been permanently suspended for a serious breach of the Terms of Service, the email hash may be retained permanently in order to prevent re-registration.
- Deletion of content: worries (stones) and replies (pebbles) written by the member are deleted together with the related data. A worry (stone) is deleted automatically 30 days after it was written, regardless of whether all replies have been filled.
- Deletion of notes: when a pebble is deleted, the whole note conversation attached to it is deleted with it. On withdrawal, all note conversations the user took part in and the notes they sent are destroyed immediately. Because the conversation itself is deleted, a note conversation in which the user was the counterparty can no longer be viewed on the other party’s screen either.
- Audit logs: security event logs are retained as required by law with the author’s identifying information removed.
3.2. Retention period for note conversations
The retention period for a note conversation is measured from the time it ends; when the period expires, the conversation and all notes within it are destroyed irrecoverably.
| Stage | Timing | Handling |
|---|---|---|
| Automatic ending after no response | 10 days from the last note | The conversation ends automatically (it can still be viewed) |
| Viewing period | 7 days from the date it ended | Retained read-only |
| Destruction | 7 days after the date it ended | The conversation and its notes are permanently deleted |
- Nature of automatic ending: automatic ending is not an expression of intent by either party, and if the other party replies before the 10 days pass the conversation continues.
- Where a party ended the conversation themselves, it is likewise retained for seven days from the date it ended and then destroyed.
- No retroactive application: for notes exchanged before this provision took effect, the periods above are calculated afresh from the effective date. Time elapsed before that date is not counted.
3.3. Retention required by law
Where retention for a certain period is required by applicable law, the information is stored separately for that period only and then destroyed.
Act on Consumer Protection in Electronic Commerce
- Records of contracts and withdrawal of offers: 5 years
- Records of payment and supply of goods: 5 years
- Records of consumer complaints or dispute handling: 3 years
Protection of Communications Secrets Act
- Access log records (access IP, time of access): 3 months
Act on Promotion of Information and Communications Network Utilization and Information Protection
- Records of labelling and advertising: 6 months
3.4. Handling of dormant accounts
- Criterion: no access for one year after the last login
- Procedure:
- Notice by email 30 days before conversion to a dormant account
- Conversion to a dormant account and separate storage if there is still no access
- Notice of scheduled permanent deletion if there is no access for a further year after conversion
- Permanent deletion 30 days after that notice
- Reactivation: a dormant account can be reactivated immediately after identity verification when a login is attempted
4. Procedure and Method for Destroying Personal Information
In accordance with Article 21 of the Personal Information Protection Act and Article 16 of its Enforcement Decree, the Company destroys personal information without delay once the retention period has passed or the purpose of processing has been achieved.
4.1. Procedure
- Selection for destruction: selected for destruction as soon as the retention period expires or the purpose of processing is achieved
- Choice of method: an appropriate method is chosen according to whether the information is in an electronic file or on paper
- Destruction: destroyed irrecoverably by the chosen method
- Record: the time of destruction, the person responsible and the method are recorded and managed
Information entered by a user is moved to a separate database once the purpose has been achieved, stored for a certain period in accordance with internal policy and applicable law, and then destroyed. Personal information moved to a separate database is not used for any other purpose except as required by law.
4.2. Methods
Personal information in electronic files
- Low-level format: permanent deletion by a method from which recovery is impossible
- Overwriting: overwriting with random data at least three times
- Physical destruction: physical destruction of the storage medium where necessary
Personal information on paper
- Shredding: shredding using a document shredder
- Incineration: incineration through a specialist disposal contractor
4.3. Timing
| Case | Timing of destruction |
|---|---|
| Withdrawal of membership | Destroyed immediately on withdrawal (the email hash is destroyed automatically after 30 days; information subject to statutory retention is excepted) |
| Dormant account | Permanently deleted one year after conversion to dormant status |
| End of a statutory retention obligation | Destroyed as soon as the retention period ends |
| Termination of the Service | Destroyed within three months of termination |
4.4. Exception (retention required by law)
Where retention is required by applicable law, the information is stored separately in a separate database or repository and managed there, and destroyed as soon as the period ends. For the information concerned and the periods, see section 3.
5. Provision of Personal Information to Third Parties
As a rule the Company does not provide users’ personal information to outside parties.
The following are exceptions.
-
Where the user’s prior consent has been obtained
- Consent is obtained after stating the recipient, the purpose, the items provided and the retention and use period.
-
Where required by law, or where an investigative authority makes a request for the purposes of an investigation in accordance with the procedures and methods prescribed by law
- Where there is a special provision in a statute, such as an urgent need for a criminal investigation
- Where there is a court warrant, or where the request follows a procedure prescribed by a statute such as the Criminal Procedure Act or the Framework Act on National Taxes
Where personal information is provided to a third party, the Company notifies the user of the following and obtains consent, in accordance with Articles 17 and 18 of the Personal Information Protection Act.
- The recipient of the personal information
- The recipient’s purpose in using the personal information
- The items of personal information provided
- The recipient’s period of retention and use of the personal information
- The fact that the user has the right to refuse consent, and any disadvantage of refusing
6. Outsourcing of Personal Information Processing
The Company outsources the processing of personal information to external specialist providers as follows in order to provide the Service.
6.1. Providers
1. Cloudflare, Inc.
Outsourced work:
- Provision of server infrastructure (Cloudflare Workers)
- Database storage and management (D1)
- Operation of a key-value store (KV)
- Distributed processing and caching
Items of personal information:
- All personal information (email address, nickname, date of birth, service usage records, access logs and the like)
Period of retention and use:
- Until withdrawal of membership or termination of the outsourcing agreement
Location and contact:
- Location: 101 Townsend St, San Francisco, CA 94107, USA
- Website: https://www.cloudflare.com
- Privacy policy: https://www.cloudflare.com/privacypolicy/
- Data centers: more than 300 cities worldwide (edge network), including Seoul and Busan in Korea
2. Resend, Inc.
Outsourced work:
- Email delivery (registration verification, password reset, important notices)
Items of personal information:
- Email address, recipient name (nickname)
Period of retention and use:
- Deleted immediately after the email is sent (delivery logs are retained for 30 days)
Location and contact:
- Location: 2261 Market Street #4990, San Francisco, CA 94114, USA
- Website: https://resend.com
- Privacy policy: https://resend.com/legal/privacy-policy
6.2. Management and supervision of providers
When entering into an outsourcing agreement, the Company sets out the following in writing and manages and supervises the provider so that it processes personal information safely, as required by Article 26 of the Personal Information Protection Act.
- A prohibition on processing personal information for any purpose other than the outsourced work
- The obligation to take technical and administrative protective measures
- Restrictions on sub-contracting
- Management and supervision of the provider
- Matters concerning liability, including compensation for loss
6.3. Notice of transfer abroad
The providers above are headquartered in the United States, and personal information may be transferred abroad. In the case of Cloudflare, data is processed through data centers in Korea (Seoul, Busan) and its global edge network is used.
Transfer details:
- Countries of transfer: the United States and worldwide (the Cloudflare edge network)
- Time of transfer: when the Service is used
- Recipients: see the providers in section 6.1 above
- Items of personal information transferred: see the items for each provider in section 6.1 above
- Recipients’ purpose in using it: performing the outsourced work (providing infrastructure, sending email)
- Period of retention and use: see the period for each provider in section 6.1 above
Additional information:
- Cloudflare holds certification under the EU-US Data Privacy Framework and for GDPR compliance.
- Resend holds SOC 2 Type II certification.
You may refuse the transfer of your personal information abroad, but if you do, your use of Forest of Stones may be restricted.
7. Rights of Users and Legal Representatives, and How to Exercise Them
A user (or, where the user is under 14, their legal representative) may exercise the following rights at any time under Articles 35 to 38 of the Personal Information Protection Act.
7.1. Right to request access (Article 35)
- In the app: available under Settings, then Account information
- Written request: by email to the personal information protection officer
- Handling period: access available within 10 days of the request
7.2. Right to request correction or deletion (Article 36)
- Correct it yourself: in the app under Settings, then Account management
- Request deletion:
- In the app under Settings, then Account management, then Withdraw membership
- By writing, email or telephone to the personal information protection officer
- Handling period: handled within 10 days of the request
- Points to note:
- Deletion is not possible where the personal information is specified as collectable by a statute
- Deletion is restricted where another statute requires retention
7.3. Right to request suspension of processing (Article 37)
- How to request: by writing, email or telephone to the personal information protection officer
- Handling period: handled within 10 days of the request
- Grounds on which suspension may be restricted:
- Where there is a special provision in a statute, or suspension is unavoidable in order to comply with a statutory obligation
- Where there is a risk of harm to another person’s life or body, or of unjustly infringing another person’s property or other interests
- Where the processing is essential to providing the Service
7.4. Withdrawal of membership (withdrawal of consent)
- In the app: Settings, then Account management, then Withdraw membership
- Email: request to hello@seonhamlabs.com
- Effect: withdrawal is processed immediately, and personal information is handled in accordance with section 3.
- Restriction on re-registration: for 30 days after withdrawal you cannot re-register with the same email address; after 30 days you may re-register freely. A member permanently suspended for breach of the Terms of Service is barred from re-registering.
7.5. Right to object to automated decision-making
- The Company does not currently make fully automated decisions, including profiling.
- If automated decision-making is introduced in future, the Company will give prior notice and obtain consent.
7.6. Points to note when exercising these rights
- For a child under 14, their legal representative may exercise these rights.
- Rights may be exercised by writing, email, telephone or a similar means.
- Where a right is exercised through a representative, a power of attorney and proof of the representative’s identity must be submitted.
- The Company takes the relevant measure within 10 days of being asked to give effect to a right, and notifies the outcome.
8. Installation and Operation of Devices that Collect Personal Information Automatically, and How to Refuse Them
8.1. Use of cookies
The Company uses cookies, which store and retrieve a user’s information from time to time.
What is a cookie?
- A very small text file that the server operating a website sends to the user’s browser and which is stored on the user’s computer.
8.2. Purposes for which cookies are used
- Maintaining automatic login: storing the refresh token securely so that the Service can be used without logging in again
- Session management: maintaining the logged-in state and authenticating the user
- Strengthening security:
- Preventing cross-site request forgery (CSRF)
- Preventing cross-site scripting (XSS) through the HttpOnly attribute
- Statistical analysis of use: improving the Service by understanding the frequency of visits and usage patterns
8.3. Types and attributes of cookies
| Cookie name | Purpose | Lifetime | Attributes |
|---|---|---|---|
| forest_token | Stores the access token (API authentication) | 15 minutes | HttpOnly, Secure, SameSite=Strict |
| forest_refresh_token | Stores the refresh token (token reissue) | 7 days | HttpOnly, Secure, SameSite=Strict |
- HttpOnly: the cookie cannot be accessed by JavaScript (defense against XSS)
- Secure: sent only over an HTTPS connection
- SameSite=Strict: sent only from the same site (defense against CSRF)
8.4. How to refuse cookies
You may choose whether cookies are installed.
Browser settings
- Chrome: Settings, then Privacy and security, then Cookies and other site data
- Safari: Preferences, then Privacy, then Cookies and website data
- Firefox: Settings, then Privacy and security, then Cookies and site data
- Edge: Settings, then Cookies and site permissions
Limitations if you block cookies
- Automatic login cannot be used
- Some parts of the Service may be difficult to use
- You will need to log in again on each visit
8.5. Tracking and advertising identifiers in the mobile app (not applicable)
The Forest of Stones app does not display advertising and does not collect advertising identifiers.
- The app contains no advertising software development kit (SDK).
- The Company does not collect, use or provide to third parties any advertising identifier (IDFA on iOS, GAID on Android).
- The app does not show the iOS App Tracking Transparency prompt. The Company does not track users across other companies’ apps and websites.
- The Company does not carry out personalized advertising or measure advertising performance.
Earlier editions of this policy (up to the fourth edition) stated that banner advertising was provided through Google AdMob. That function was never actually made available to users, and the related SDK and code have been removed from the app.
If advertising is introduced in future, the Company will amend this policy to give prior notice of the items collected, the purposes and how to refuse, and will follow the consent procedures required by law.
8.6. Push notifications in the mobile app
The Company uses mobile push notifications in order to send service notifications (a new pebble, a note or reply received, notices and the like).
- Item collected: device token (Apple APNs token on iOS, Google FCM token on Android)
- Purpose: sending transactional notifications directly related to use of the Service
- When collected: on first launch of the app, or when notification permission is granted
- Retention period: retained while notification permission is in place; deleted on withdrawal of membership or when the token changes
- How to opt out:
- iOS: Settings, then Notifications, then Forest of Stones, then turn off Allow Notifications
- Android: Settings, then Apps, then Forest of Stones, then Notifications, then turn off
- In the app: Settings, then Notification settings, where each type can be adjusted
- You can use the Service normally even if you refuse notifications.
8.7. Access permissions in the mobile app
In accordance with Article 22-2 of the Network Act, the Company gives notice of the access permissions required within a mobile device in order to provide the Service, as follows.
The Forest of Stones app has no required access permissions. Even if you allow none of the optional permissions below, you can use all of the core functions of the Service normally (writing stones, replying with pebbles, note conversations and the like).
Optional access permissions
| Permission | Purpose | When requested | If not granted |
|---|---|---|---|
Notifications (iOS notifications / Android POST_NOTIFICATIONS) |
Sending service notifications such as a new pebble, a note or reply received, and notices | When you choose “Turn on notifications” on the in-app explanation screen, or when you turn notifications on under Settings, then Notification settings | Only notifications are not received; there is no restriction on using the Service |
Notifications are the only optional permission. App tracking (iOS ATT) and the advertising identifier (Android AD_ID), which appeared in earlier editions of this policy (up to the fourth edition), were removed along with the advertising function — the app no longer shows a tracking consent prompt and does not access an advertising identifier (see section 8.5).
- The Company does not request notification permission as soon as the app launches. It first explains on an in-app screen why the permission is needed, and shows the operating system’s permission prompt only to users who agree.
- If you choose “Later” on the explanation screen, the operating system’s permission prompt is not shown, and you can turn notifications on at any time under Settings, then Notification settings.
Permissions that do not require separate consent
The following are “normal permissions” on Android. They do not access personal information or information stored on the device and are not subject to individual consent.
- Internet access (
INTERNET): communication with the service servers - Receive boot completed (
RECEIVE_BOOT_COMPLETED): keeping scheduled notifications working after the device restarts
Permissions not collected
The Company neither requests nor accesses the following permissions, which are not needed to provide the Service.
- Camera, photos, media and storage, location, contacts, microphone, call logs, text messages, calendar, physical activity
- Advertising identifiers (iOS
IDFA/ AndroidAD_ID) and the iOS App Tracking Transparency (ATT) permission
How to withdraw a permission
You can withdraw a permission you have granted at any time as follows.
- iOS: Settings, then Forest of Stones, then Notifications
- Android: Settings, then Apps, then Forest of Stones, then Permissions, then change each item
- In the app: Settings, then Notification settings, where you can adjust whether notifications are received
Where permissions cannot be set individually because the operating system version is too old, you can obtain individual consent functionality by upgrading through the device manufacturer, or withdraw the permission by deleting the app.
9. Measures to Secure Personal Information
In accordance with Article 29 of the Personal Information Protection Act and the Standards for Measures to Secure Personal Information (a public notice), the Company takes the following measures in order to manage users’ personal information safely.
9.1. Administrative measures
- Designation of a personal information protection officer and training of staff
- Establishment and implementation of an internal management plan
- Regular internal inspections
- Minimizing the number of staff who process personal information, and managing access rights
- Regular security training for those who handle personal information
9.2. Technical measures
- Password encryption: bcrypt (12 salt rounds); storage in plain text is prohibited
- Retention of access records and prevention of tampering: security logs stored encrypted, with integrity verification
- Security measures against hacking and the like:
- Encrypted communication over HTTPS (TLS 1.3)
- Cloudflare Web Application Firewall (WAF) enabled
- Operation of DDoS defenses
- Encryption of personal information:
- Encryption in transit (TLS 1.3)
- Encryption at rest (encrypted Cloudflare D1 storage)
- Protection against malicious code: defense against cross-site scripting (XSS) using the DOMPurify library
- Access control:
- Authentication based on JSON Web Tokens (JWT)
- A two-token structure of access token (valid for 15 minutes) and refresh token (valid for 7 days)
- A refresh token rotation (RTR) policy, with immediate invalidation on detection of reuse
- Rate limiting:
- Distributed rate limiting based on Cloudflare Durable Objects
- Login attempts: locked for 10 minutes after 5 failures
- API requests: limited to 60 per minute per IP address
- Session management:
- HttpOnly and Secure cookies (preventing XSS attacks)
- The SameSite=Strict attribute (preventing CSRF attacks)
9.3. Physical measures
- Physical access control for the servers on which personal information is stored
- Compliance with Cloudflare’s Tier 3+ data center security policy:
- 24-hour physical security monitoring
- Biometric access control
- Redundant power supply and cooling
9.4. Response to a personal information breach
- A response team is formed immediately if a breach of personal information occurs
- Users are notified without delay once the breach is confirmed
- The breach is reported to the relevant authorities, including the Korea Internet & Security Agency (KISA)
10. Personal Information Protection Officer and Staff
In accordance with Article 31 of the Personal Information Protection Act, the Company has designated a personal information protection officer as follows, in order to protect users’ personal information and handle complaints relating to it.
Personal information protection officer
- Name: 김선민 (Kim Sunmin)
- Position: Representative
- Organization: 선함연구소 (Seonham Labs)
- Email: hello@seonhamlabs.com
- Contact: please enquire by email.
Department responsible for personal information protection
- Department: 선함연구소 (Seonham Labs)
- Person responsible: 김선민 (Kim Sunmin)
- Email: hello@seonhamlabs.com
How to seek redress
You may raise with the personal information protection officer and the responsible department any enquiry, complaint or request for redress relating to the protection of personal information arising from your use of the Service.
The Company will answer your enquiry promptly and fully. An answer is provided within 10 days of receipt.
11. Advice and Reporting on Infringement of Personal Information
If you need to report an infringement of personal information or seek advice, please contact the bodies below.
Personal Information Infringement Report Center (Korea Internet & Security Agency)
- Telephone: 118 (within Korea, no area code)
- Website: https://privacy.kisa.or.kr
- Function: reporting infringements of personal information, requesting advice
Personal Information Dispute Mediation Committee
- Telephone: 1833-6972 (within Korea, no area code)
- Website: https://www.kopico.go.kr
- Function: applications for mediation of personal information disputes, collective dispute mediation (civil resolution)
Cyber Investigation Division, Supreme Prosecutors’ Office
- Telephone: 1301 (within Korea, no area code)
- Website: https://www.spo.go.kr
- Function: investigation of cybercrime
Cyber Bureau, Korean National Police Agency
- Telephone: 182 (within Korea, no area code)
- Website: https://ecrm.police.go.kr
- Function: reporting cybercrime and seeking advice
Translator’s note — not part of this Privacy Policy. The bodies above serve residents of the Republic of Korea. If you are elsewhere, you may also contact the data protection authority in your own country. Wherever you are, you can write to hello@seonhamlabs.com first.
12. Protection of Children’s Personal Information
Only those aged 19 and over may register with the Company. The Company does not collect the personal information of children under 19.
13. Changes to this Privacy Policy
Content may be added to, deleted from or amended in this Privacy Policy following changes in law, policy or security technology.
13.1. Notice of changes
-
Material changes: notified at least 30 days before the effective date through the in-app notices and by email.
- A change materially affecting users’ rights
- The addition of a new item of personal information to be collected
- The addition of provision to a third party or of outsourced processing
-
Ordinary changes: notified at least seven days before the effective date through the in-app notices.
- Minor changes such as rewording or correcting typographical errors
- Formal changes following an amendment to legislation
13.2. Management of the change history
- The amended Privacy Policy can be viewed in the app.
- Earlier versions of the Privacy Policy are also retained and made available for inspection.
13.3. Consent to changes
- Material changes take effect after the user’s separate consent has been obtained.
- If you do not consent, your use of the Service may be restricted, and you may withdraw your membership.
Addendum
Article 1 (Effective date)
This Privacy Policy (fifth edition) takes effect from October 6, 2026. The immediately preceding edition (the fourth) applies from September 22, 2026 to October 5, 2026.
Article 2 (Amendment history)
Fifth edition (effective October 6, 2026; re-notified September 8, 2026)
- Deletion of all provisions relating to the bookmark (stone rubbing) function following its discontinuation (this amendment reduces the items collected and is not disadvantageous to users)
- Removal of bookmark storage from the service usage records among the items collected automatically (1.1), and of the number of bookmarks that could be stored from the activity data
- Removal of bookmarks from the lists of core functions in the purposes of use (2.2) and the access permissions notice (8.7)
- Deletion of the provision on retaining bookmark snapshots on withdrawal (3.1)
- Deletion of all provisions relating to points and in-app purchases as no such scheme is operated (this amendment reduces the items collected and is not disadvantageous to users)
- Removal of points data (balance and transaction history) from the items collected automatically (1.1)
- Removal of management of points earned, topped up and spent from the purposes of use (2.2)
- Deletion of the provision on expiry of points on withdrawal (3.1)
- Removal of “likes” activity, which is not provided, from the service usage records among the items collected automatically (1.1)
- Correction of the time at which a stone is deleted on withdrawal (3.1) — the previous wording (“seven days after completion”) was corrected to match actual operation (30 days after being written, regardless of completion)
- The above amendments were reflected in the version notified on August 27, 2026 and re-notified (the effective date of October 6, 2026 was unchanged)
Fifth edition as first notified (notified August 27, 2026)
- A new provision on access permissions in the mobile app (8.7) — notice of access permissions under Article 22-2 of the Network Act
- It states that there are no required access permissions, and explains the purpose of the optional permission (notifications), when it is requested, the effect of not granting it and how to withdraw it
- It states the normal permissions that do not require separate consent (internet access, receive boot completed) and the permissions that are not requested (camera, photos, location, contacts, microphone and the like)
- Deletion of all provisions relating to in-app advertising and advertising identifiers following the removal of the Google AdMob SDK and the iOS App Tracking Transparency request from the app (this amendment reduces the items collected and is not disadvantageous to users)
- Removal of advertising identifiers (IDFA, GAID) from the items collected automatically (1.1)
- Removal of Google LLC (AdMob) from the outsourced processing (6.1)
- The section on tracking and advertising identifiers (8.5) was changed to “not applicable”, stating that no advertising is displayed, no identifier is collected and no ATT prompt is shown
- Removal of the rows for app tracking (ATT) and the advertising identifier (
AD_ID) from the optional permissions table (8.7), and their addition to the list of permissions not requested
- The above amendments were reflected in the version notified on August 26, 2026 and re-notified (the effective date of October 6, 2026 was unchanged)
Fourth edition (effective September 22, 2026; notified August 23, 2026)
- Amendment of the items collected (1.2), the purposes of use (2.2, 2.3) and the handling of withdrawal (3.1) following the change of the note function to a conversation
- New items for collecting note conversation participants and ending information, and an explicit principle of destruction by conversation
- A new provision on the retention period for note conversations (3.2) — automatic ending after no response (10 days), the viewing period after ending (7 days), the time of permanent destruction and the principle of no retroactive application
- Correction of the character count for note contents (10 to 200 characters became 1 to 200 characters)
- Following the change of the notification date, the effective date was adjusted from September 8, 2026 to September 22, 2026
Third edition (effective June 9, 2026)
- Addition of provisions on push notifications: the device token among the items collected (1.1), the purpose of use (2.3) and how to opt out (8.6)
Second edition (effective May 18, 2026)
- Update of the items collected, the purposes of use and the handling of withdrawal following the addition of the note function
First edition (effective March 1, 2026)
- First enactment and entry into force
Article 3 (Duty to give notice)
Where this Privacy Policy changes, notice is given according to how material the change is, as follows.
- Material changes: notified from at least 30 days before the change through the in-app notices and by email
- Ordinary changes: notified from at least seven days before the change through the in-app notices
Article 4 (Governing law and jurisdiction)
The interpretation and application of this Privacy Policy is governed by the law of the Republic of Korea. A dispute arising between a user and the Company in relation to this Privacy Policy is governed by the law of the Republic of Korea and is subject to the rules on jurisdiction under the Korean Civil Procedure Act.
Translator’s note — not part of this Privacy Policy. The Article above states the governing law and jurisdiction set out in the Korean text. Mandatory data protection rules of your country of residence may nonetheless apply to you. This note is added for readers of this translation and adds nothing to, and takes nothing from, the policy.
Governing Language
This English text is a reference translation provided for the convenience of our users. The Korean version is the governing text. Where there is any difference between the Korean version and this translation, the Korean version applies.
The Korean version is available at forest.seonhamlabs.com/privacy.